Technology Overview
SAP Business Technology Platform (BTP) is SAP’s multi-tenant cloud platform:
- identity/trust management (XSUAA, IAS/IPS)
- integration (Integration Suite/CPI, Connectivity/Destination service, Cloud Connector)
- data/AI services (HANA Cloud, AI Core), and multiple application runtime environments
all organized under a single account hierarchy.
Account hierarchy:
Global Account
└─ Directory (optional, for grouping)
└─ Subaccount ← unit of identity zone, entitlements, trust config
└─ Space (Cloud Foundry) | Namespace (Kyma) | Cloud ABAP system
Each Subaccount gets its own XSUAA/IAS identity zone, its own set of Destinations, Trust Configuration entries, and Role Collections - it is the natural unit of scoping for a BTP assessment.
Within Cloud Foundry, a Subaccount contains one or more Orgs & Spaces; the Cloud Foundry Space Developer role (routine for any app developer) is the role that matters most offensively.
Two identity planes sit above the subaccount: the SAP ID Service / S-user (SAP-managed default IdP for Global Account/Support Portal admin) and a customer’s own federated corporate IdP via IAS/IPS.
Four application runtime environments, not all present on every tenant:
| Environment | Runtime | Identity | Notes |
|---|---|---|---|
| Cloud Foundry (CF) | cf push apps, buildpacks | XSUAA | Most common; default *.cfapps.<region>.hana.ondemand.com routes - see Cloud Foundry URL pattern/schema |
| Kyma | Kubernetes + Istio | XSUAA / OIDC via Istio | No single static domain; per-cluster - see Kyma URL pattern/schema |
| ABAP Environment (Steampunk) | Cloud ABAP, RAP/CDS | XSUAA + ABAP-native auth | Restricted ABAP; Communication Arrangements bridge to on-prem/BTP |
| Neo | Legacy, SAP-managed JVM/HANA runtime | SAML/OAuth | Being phased out; still found in older tenants |
Connectivity between BTP and on-premise systems runs through the Destination service (stores connection config, sometimes cleartext credentials and Cloud Connector (the on-prem bridge; see SAP Cloud Connector).
